PT-2026-30384 · Tenda · M3

Doma

·

Published

2026-04-04

·

Updated

2026-04-05

·

CVE-2026-5567

CVSS v2.0

9.0

High

AV:N/AC:L/Au:S/C:C/I:C/A:C
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-5567

Affected Products

M3